Privacy PolicyEffective September 22, 2026Last updated: September 22, 2026. This Policy explains how SATO Technologies Corp, operating Qritical AI, handles personal information in connection with its website, accounts, GPU compute, storage, support and Cowork features. Address: 289 rue Dugas, Joliette (Québec) J6E 4H1, Canada. Privacy Officer: Romain Nouzareth, privacy@qritical.ai.
1. Our role and customer workloadsWe determine the purposes of account administration, billing, platform security and our own customer support. For personal information that a business customer puts into a workload, we generally act as its service provider under its instructions and the applicable agreement, including a DPA where required. That customer is responsible for its own notices and lawful instructions. These roles depend on actual processing, not labels alone.If your information is in another customer's workload, first contact that customer to exercise rights concerning its processing. We will assist as required by law and our agreement and will not use this referral to deny rights that apply directly against us. This Policy does not govern an independent application or external service that a customer chooses to run or connect; its provider may have separate practices.
2. Information we handle and its sourcesAccount and team information: name, email, account identifiers, password hash where password authentication is used, authentication records, team membership, permissions, and contractual acceptance records. We receive these from you, authorized administrators and your interactions with the platform.Billing information: billing contact and address, tax details you supply, payments, paid and promotional balances, usage charges, transaction identifiers, payment status and limited payment-method details returned by the payment processor. Stripe handles card entry and payment processing; we do not store full card numbers or card security codes in our application database.Technical and operational information: IP address, browser and device information, request and access logs, resource identifiers and configurations, location selections, metering, security events and support communications. Deployment failures may produce console excerpts, currently up to 2,000 characters per captured excerpt. Logs can contain content, personal information or secrets printed by your software, not just filenames. Avoid including credentials or unnecessary sensitive data in logs or support requests.Connected services: authorization tokens and, where issued and needed, refresh tokens, granted scopes, selected folders, associated account identifiers or email addresses, and synchronization metadata. We also handle third-party credentials you choose to provide, such as Hugging Face tokens. We receive connected files and metadata from the provider under your authorization.Workload information: files, code, model weights, prompts, outputs and other data you submit or generate are hosted and processed on infrastructure used to supply your workload. They can be personal information even if our staff never view them. Temporary files, caches, snapshots and backups can also contain that information.
3. Purposes and permissionsWe use information to provision and operate requested resources, authenticate users, administer teams and integrations, meter usage, process payments, provide support, communicate service changes, troubleshoot failures, secure the platform, prevent fraud and abuse, respond to rights requests and satisfy legal obligations. We limit operational analysis to information reasonably needed for those purposes and do not use workload content for unrelated product research.We rely on consent where required and on applicable legal permissions where consent is not required. Optional uses requiring consent are presented separately and are not authorized merely by accepting the Terms. Refusing information necessary for an account, payment or requested integration may prevent us from providing that feature. Withdrawing optional consent does not make earlier lawful processing unlawful.We do not sell personal information or use Customer Content to train our own models, third parties' general-purpose models, or advertising profiles. Executing an inference or training job that you request within your workload is part of providing that job. We do not guarantee that independent software or external providers you select follow the same practices.
4. Cloud connections, AI and access to contentDropbox, Google Drive and OneDrive connections access data within the scopes and folders you authorize to provide the synchronization feature. Our source synchronization is read-only. Copies are created in your workload and may appear in its temporary files or backups. Disconnecting or revoking permission prevents future authorized access but does not automatically delete previously copied files; delete those through the relevant workload or contact us.Human access to workload or connected content is restricted to what is necessary and lawfully permitted: support you authorize, security or abuse investigation, required service operations, or legal obligations. Access to Google-derived data follows any stricter applicable Google restrictions. We do not routinely read customer workloads or manually review their outputs.Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google-derived data for advertising, credit decisions, sale to data brokers or training general-purpose AI models. Human access and onward transfers occur only within the applicable permitted exceptions. A business transfer involving such data requires any consent demanded by Google's rules.If you enable an external model API or tool, the data it receives depends on your configuration. Review its permissions and privacy terms. Do not assume a model runs exclusively within your GPU workload merely because it is accessible through Cowork.
5. Recipients and service providersWe disclose information only as reasonably necessary for the stated purposes, with consent where required or as law otherwise permits. Current service categories include Targon, operated by Manifold Labs, Inc., for GPU workload infrastructure; Stripe for payments; Amazon Web Services for transactional email and file storage; MongoDB Atlas for databases; Vercel for application hosting; and Cloudflare for DNS and network services.Providers receive information relevant to their function and are subject to appropriate contractual and security requirements. A payment provider may also process information for its own regulatory or fraud-prevention purposes under its own privacy notice. Customer-authorized team administrators can access information and control resources within their permissions; check your organization's policies before placing personal material in its account.We may disclose necessary information to professional advisers or authorities where permitted or required by law, to establish or defend legal claims, or to respond to a qualifying emergency. A request does not automatically justify disclosure; we assess its legal basis and scope. A potential or completed business transaction may involve necessary information under confidentiality and legally required safeguards, notices and consents. This is not unrestricted permission to sell customer data.
6. Locations and cross-border processingGPU workloads currently run in the United States through our infrastructure provider. Files synchronized into them are therefore processed outside Québec and Canada. The selected compute region does not by itself establish the location of payments, support access, network services, telemetry, backups or other providers' processing.Account and service administration involves processing in Canada and by service providers whose operations may be outside Québec or Canada, including in the United States. We do not offer a Canada-only processing commitment under this Policy. Contact privacy@qritical.ai before deployment if you require specific location information or a contractual residency commitment.Information processed abroad may be accessible to courts, law enforcement or other authorities under local law. We assess transfers and put required contractual safeguards in place under applicable law. A transfer disclosure or your choice of region does not replace our obligations. Do not submit information subject to a residency restriction unless the agreed service arrangement actually meets it. No future Canadian capacity or particular residency guarantee is promised unless expressly agreed.
7. Retention and deletionWe retain information only for as long as needed for the stated purposes and applicable legal requirements. Account information supports the active account; after closure, only information justified by billing, tax, security, claims or other lawful retention is kept. Tax-record obligations do not justify indefinite retention of all profile information or workload content. Access to retained information is restricted.Our retention schedule includes: notifications, 30 days; deployment diagnostic excerpts, 90 days; active connection tokens, until disconnection or closure, followed by deletion from active systems. Other retention periods are determined by the purpose of the record, applicable legal requirements, the need to investigate incidents or resolve disputes, and the expiry of backup cycles. Contact our Privacy Officer for information about a particular category. Records no longer required for these purposes are deleted or anonymized as permitted by law.Terminating a workload deletes its active container storage and any linked temporary volumes designated for deletion. Separately created persistent volumes remain until deleted or account closure, subject to the applicable service terms. Deleting active content does not mean every backup copy is immediately erased. Residual copies expire under the applicable retention schedule, remain protected, and are not used for unrelated purposes. Legal preservation requirements may delay specific deletions.Deletion of workload content is separate from retention of resource metadata, billing evidence and security or incident records. Disconnecting a cloud source does not erase synchronized copies already present elsewhere. We explain applicable exceptions when responding to a deletion request.
8. Safeguards and incidentsWe use organizational and technical safeguards appropriate to the information's sensitivity, including access restrictions, secure credential handling and encryption where implemented. Protection of traffic and data within customer-configured workloads also depends on the software, protocols and settings selected by the customer.You must secure your own software, access keys, public endpoints and backups. These responsibilities do not remove ours. No security measure eliminates all risk. We investigate confidentiality incidents, take appropriate mitigation measures, and notify affected customers, individuals and competent regulators when required by applicable law and contracts. This includes Québec notification duties and, where applicable, federal PIPEDA breach duties. Not every security event requires public or individual notice.
9. Cookies and communicationsThe service uses session cookies for authentication, preference cookies for choices such as theme, and short-lived security cookies for connection flows. We do not use cookies for targeted advertising. Service providers may use cookies or similar technologies necessary for payments, security and delivery of embedded features. If optional tracking is introduced, we provide the required notice and obtain required consent before activation.Browser controls can block or delete cookies, but essential features may then fail. Operational messages concern authentication, billing, resources or legal changes. Promotional messages, if offered, use the permissions and unsubscribe mechanisms required by law; declining marketing does not stop necessary service communications.
10. Your rights and complaintsDepending on applicable law, you may request access, correction, deletion, withdrawal of consent and portability of eligible computerized information in a structured, commonly used format. Portability does not necessarily cover inferred or derived information or every service record. Rights are subject to lawful conditions and exceptions, including protection of other people and required record retention. They do not require us to recover content no longer held.Write to privacy@qritical.ai with enough information to identify the account and request. We verify identity proportionately and request only necessary information. We respond within the applicable legal period, generally 30 days for Québec access and rectification requests, and explain any legally permitted extension, refusal or limitation and available recourse. We do not condition statutory rights on surrendering a claim against us.Our Privacy Officer oversees privacy governance and complaints. We document and assess complaints, involve relevant personnel, and communicate our response and appropriate corrective measures. You may contact the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada, as applicable. Other legally competent regulators remain available. Internal contact is not a prerequisite to a statutory complaint.
11. Age and changesAccounts are intended for adults aged 18 or older. If we learn that an underage person has opened an account, we take appropriate steps to restrict it and address information unlawfully collected. This does not imply that customer workloads can never contain information about minors; the customer must have the legal authority and safeguards for any such processing.We publish updates with an effective date and provide appropriate notice of material changes. We obtain new consent where required before a new use. A policy update does not retroactively authorize a use or disclosure that previously required consent. Contact privacy@qritical.ai for questions or an accessible copy of this Policy.